ubuntu-12.04.3-desktop-amd64.iso md5sum missing from https://help.ubuntu.com/community/UbuntuHashes
Bug #1219589 reported by
eviljoel
This bug affects 2 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
ubuntu-docs (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
ubuntu-
information type: | Private Security → Public Security |
To post a comment you must log in.
Our distribution directories such as http:// mirror. anl.gov/ pub/ubuntu- iso/DVDs/ ubuntu/ 12.04/release/ have SHA256SUMS and SHA256SUMS.gpg files that would be safer to use -- the SHA256SUMS file is gpg signed with a detached signature, and this does a significantly better job protecting the data you care about -- the hash of the ISO.
HTTPS is convenient, but someone in a position to perform a DNS poisoning attack and convince one of the many certificate authorities to issue a fraudulent certificate can bypass the HTTPS verifications easily.
Thanks